Re: [SECURITY] [DSA 740-1] New zlib packages fix denial of service

2005-07-07 Thread Roberto Gordo Saez
On Wed, Jul 06, 2005 at 04:45:01PM +0200, Michael Stone wrote: - Debian Security Advisory DSA 740-1 [EMAIL PROTECTED] http://www.debian.org/security/Michael Stone July 06,

Shadow passwords

2005-07-07 Thread Johann Spies
I am busy building two new proxy servers. I installed the first from debian-install CD with the normal installer. As an exercise in disaster recovery I decided to install the second from a CD I have build with dfsbuild on the first one. On the second machine Tiger reports: user is not

Re: /dev/log

2005-07-07 Thread Russell Coker
On Wednesday 06 July 2005 05:05, Ian Eure [EMAIL PROTECTED] wrote: It's used by syslogd. Not 100% sure on this, but I believe it's how user-space apps send messages to syslog (e.g. with syslog(3)). If that's the case, it would need to be mode 666 for syslog(3) to work. It doesn't have to be

Re: Shadow passwords

2005-07-07 Thread Bill Marcum
On Thu, Jul 07, 2005 at 09:49:17AM +0200, Johann Spies wrote: I am busy building two new proxy servers. I installed the first from debian-install CD with the normal installer. As an exercise in disaster recovery I decided to install the second from a CD I have build with dfsbuild on the first

Re: Shadow passwords

2005-07-07 Thread Johann Spies
On Thu, Jul 07, 2005 at 04:48:51AM -0400, Bill Marcum wrote: On Thu, Jul 07, 2005 at 09:49:17AM +0200, Johann Spies wrote: I am busy building two new proxy servers. I installed the first from debian-install CD with the normal installer. As an exercise in disaster recovery I decided to

Re: [SECURITY] [DSA 741-1] New bzip2 packages prevent decompression bomb

2005-07-07 Thread steve
Hallo, Ik ben op vakantie tot 20 juli. Voor support vragen kunt u contact opnemen met onze supportdesk. Voor sales en andere vragen kunt u mailen naar [EMAIL PROTECTED] Met vriendelijke groet, Steve Karnadi Hello, I am on vacation until the 20th of July. You can contact our supportdesk

Re: Where is the security announcement?

2005-07-07 Thread Robin Schroeder
martin f krafft schrieb: So Debian has had (and continues to have) problems with the security archive. This has been widely publicised, giving the world a rather shameful image of our projecti and produce. Ignoring the causes of the problems, which undoubtedly need to be fixed ASAP, no

gpg-errors with apt

2005-07-07 Thread Johann Spies
I have asked this on debian-user but got no response: I have read http://www.debian-administration.org/articles/174 about this topic and have done what the article suggested: ~# gpg --keyserver keyring.debian.org --recv 4F368D5D Got a timeout here. Or if you wish you can download it from the

Re: gpg-errors with apt

2005-07-07 Thread Steve Kemp
On Thu, Jul 07, 2005 at 12:22:36PM +0200, Johann Spies wrote: I have read http://www.debian-administration.org/articles/174 about this topic and have done what the article suggested: ~# gpg --keyserver keyring.debian.org --recv 4F368D5D This imports the key for the Debian Unstable archive.

Re: Where is the security announcement?

2005-07-07 Thread martin f krafft
also sprach Robin Schroeder [EMAIL PROTECTED] [2005.07.07.1133 +0200]: I got at least security announcements from debian-security-announce@lists.debian.org Not between 3 June and 30 June. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL

Re: gpg-errors with apt

2005-07-07 Thread Johann Spies
Hello Steve, On Thu, Jul 07, 2005 at 12:26:32PM +0100, Steve Kemp wrote: On Thu, Jul 07, 2005 at 12:22:36PM +0200, Johann Spies wrote: I have read http://www.debian-administration.org/articles/174 about this topic and have done what the article suggested: ~# gpg --keyserver

Re: gpg-errors with apt

2005-07-07 Thread Steve Kemp
On Thu, Jul 07, 2005 at 02:14:51PM +0200, Johann Spies wrote: Ok, but the archive on archive3.sun.ac.za is just a mirror from a primary debian upstream source. Do I have to generate a spesific key for my server? Strange .. but no you need do nothing with your key(s). NO_PUBKEY

Re: gpg-errors with apt

2005-07-07 Thread Johann Spies
On Thu, Jul 07, 2005 at 01:39:57PM +0100, Steve Kemp wrote: On Thu, Jul 07, 2005 at 02:14:51PM +0200, Johann Spies wrote: Ok, but the archive on archive3.sun.ac.za is just a mirror from a primary debian upstream source. Do I have to generate a spesific key for my server? Strange ..

RE: [SECURITY] [DSA 741-1] New bzip2 packages prevent decompression bomb

2005-07-07 Thread Christina Miller
Hey Lance, Do you know how I can get myself off of this list? Somehow I signed up under my alias, so I can't just send a message from my email account. Christina -Original Message- From: Martin Schulze [mailto:[EMAIL PROTECTED] Sent: Thursday, July 07, 2005 5:06 AM To: Debian

Re: [SECURITY] [DSA 741-1] New bzip2 packages prevent decompression bomb

2005-07-07 Thread Frans Pop
On Thursday 07 July 2005 15:17, Christina Miller wrote: Do you know how I can get myself off of this list? Somehow I signed up under my alias, so I can't just send a message from my email account. Use the unsubscribe button on this page after filling in the address you used to subscribe:

Re: [SECURITY] [DSA 742-1] New cvs packages fix arbitrary code execution

2005-07-07 Thread steve
Hallo, Ik ben op vakantie tot 20 juli. Voor support vragen kunt u contact opnemen met onze supportdesk. Voor sales en andere vragen kunt u mailen naar [EMAIL PROTECTED] Met vriendelijke groet, Steve Karnadi Hello, I am on vacation until the 20th of July. You can contact our supportdesk